This plugin extracts DEX files from compiled OAT files (ELF) that are used by the Android Runtime.
Recognizes verified OAT layouts 039, 045, 064, 079, 124, 131, 138, 170, 183, 195, and 199. Other versions are rejected. Embedded DEX extraction is supported for 039/045/064/079 and 124/131 builds with embedded DEX data. External VDEX/DEX files (required by later versions) are not loaded by this plugin.
Building from source: adjust the version number and run the build-xxx script.
Parser limits default to 256 MiB of input, 1 MiB of key/value data, and 256 MiB of
total extracted DEX data (including repeated entries). Override them at JVM startup
with -Djeb.oat.maxInputBytes=N, -Djeb.oat.maxKeyValueBytes=N, and
-Djeb.oat.maxDexBytes=N, respectively; values are positive integers in bytes.
Parsing is strict by default. Set -Djeb.oat.recoverDex=true at JVM startup to
enable heuristic recovery after a DEX record error in a recognized layout. Recovery
scans at most 4 KiB from the failing record, validates candidate DEX headers, and
ignores repeated offsets. Recovered results are marked in the unit description and
may be incomplete, even when the extracted count matches the declared count.
Invalid OAT headers/table offsets and resource-limit violations still fail.
Layout references: AOSP Android 5.1, Android 7.0, and Android 8.1.
OAT HEADER FORMAT: base is version 39, exceptions start in version 64+
(all entries are 32-bit words)
magic number ('oat\n')
OAT version ('NNN\0')
checksum of header
ISA
ISA features bitmask
Dex file count
OAT Dex Files Offset // ADDED in v127+
offset of executable code section
interpreter to interpreter bridge offset // REMOVED in v170+
interpreter to compile code bridge offset // REMOVED in v170+
jni dlsym lookup (trampoline) offset
jni dlsym lookup critical trampoline offset // ADDED in v180+
portable imt conflict trampoline offset // ABSENT in supported v64+
portable resolution trampoline offset // ABSENT in supported v64+
portable to interpreter bridge offset // ABSENT in supported v64+
quick generic jni trampoline offset
quick imt conflict trampoline offset
quick resolution trampoline offset
quick to interpreter bridge offset
nterp trampoline offset // ADDED in v190+
image patch delta // REMOVED in v162+
image file location oat checksum // BECOMES "boot image checksum" in v164+ / REMOVED in v166+
image file location oat data begin // REMOVED in v162+
key value store length
* key value store - hold some info about compilation
(start of dex headers; use OAT Dex Files Offset when present)
dex file location size
* dex file location path string
dex file location checksum
dex file pointer from start of oatdata